Clawvet API Secret Flaw Exposed
A hard-coded JWT secret in self-hosted clawvet API servers allows remote attackers to bypass authentication and harvest sensitive data.
3 results for “cve-2026-62241”
A hard-coded JWT secret in self-hosted clawvet API servers allows remote attackers to bypass authentication and harvest sensitive data.
A hard-coded JWT secret in self-hosted Clawvet API versions prior to 0.7.5 allows unauthenticated access to sensitive user information.
A critical vulnerability in clawvet API versions before 0.7.5 allows unauthenticated attackers to forge session cookies and access sensitive user information.